Splunk Enterprise

How to extract time from log

esalmon
Explorer

Hi,

I want to extract the timestamp from my log and make it the official _time in Splunk and I'm having difficulties doing that. I'd like to keep the date current as there is no date in the log files.

This is an example of what a log looks like with the Splunk time:

esalmon_0-1591835820262.png

And this is my props.conf:

esalmon_1-1591835864116.png

I just want the time in the logs to match the time in Splunk, and I am not sure what I am doing wrong. Please help

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...